2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-11044 | HIGH | 7.8 | 0.1% | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The ch... |
| CVE-2016-11043 | HIGH | 7.5 | 0.2% | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with M(6.0) software. The S/MIME implementation in EAS uses DES (where... |
| CVE-2016-11042 | HIGH | 7.5 | 0.4% | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. There is a SIM Lock bypass. The S... |
| CVE-2016-11041 | MEDIUM | 4.6 | 0.1% | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with KK(4.4) software. Attackers can bypass the lockscreen by sending ... |
| CVE-2016-11024 | CRITICAL | 9.8 | 1.4% | Mar 30, 2020 | odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued. |
| CVE-2016-11023 | CRITICAL | 9.8 | 1.4% | Mar 30, 2020 | odata4j 0.7.0 allows ExecuteCountQueryCommand.java SQL injection. NOTE: this product is apparently discontinued. |
| CVE-2016-11022 | HIGH | 7.2 | 3.2% | Mar 23, 2020 | NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code wi... |
| CVE-2016-1000111 | MEDIUM | 5.3 | 2.4% | Mar 11, 2020 | Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not pro... |
| CVE-2016-1487 | HIGH | 8.8 | 2.9% | Mar 9, 2020 | Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execut... |
| CVE-2016-6918 | CRITICAL | 9.8 | 1.9% | Mar 9, 2020 | Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading file... |
| CVE-2016-1159 | MEDIUM | 6.5 | 3.3% | Mar 9, 2020 | In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain... |
| CVE-2016-11021 | HIGH | 7.2 | 68.5% | Mar 9, 2020 | setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in th... |
| CVE-2016-11020 | CRITICAL | 9.8 | 2.9% | Feb 25, 2020 | Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote... |
| CVE-2016-4606 | CRITICAL | 9.8 | 3.3% | Feb 21, 2020 | Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrar... |
| CVE-2016-3182 | MEDIUM | 5.5 | 1.5% | Feb 20, 2020 | The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of ser... |
| CVE-2016-3181 | — | — | — | Feb 20, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-3182. Reason: This candidate is a duplicate of C... |
| CVE-2016-1000109 | MEDIUM | 5.3 | 5.0% | Feb 19, 2020 | HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applicat... |
| CVE-2016-1000005 | CRITICAL | 9.8 | 1.4% | Feb 19, 2020 | mcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if ot... |
| CVE-2016-1000004 | CRITICAL | 9.8 | 0.7% | Feb 19, 2020 | Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_d... |
| CVE-2016-5710 | MEDIUM | 4.6 | 0.7% | Feb 11, 2020 | NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspeci... |
| CVE-2016-1544 | LOW | 3.3 | 0.9% | Feb 6, 2020 | nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion). |
| CVE-2016-9928 | HIGH | 7.4 | 4.5% | Feb 6, 2020 | MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or... |
| CVE-2016-7524 | MEDIUM | 6.5 | 2.2% | Feb 6, 2020 | coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted fil... |
| CVE-2016-7523 | MEDIUM | 6.5 | 2.6% | Feb 6, 2020 | coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted fil... |
| CVE-2016-4676 | HIGH | 7.5 | 2.0% | Feb 3, 2020 | A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which c... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now